Vulnerability index

Browse CVEs

1,208 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
Pdfreactor CRITICAL 9.1
CVE-2019-12154

XXE in the XML parser library in RealObjects PDFreactor before 10.1.10722 allows attackers to supply malicious XML content in externally referenced r…

Fix: 10.1.10722+
Fix from $2,300 2019-06-11
Token Macro HIGH 7.5
CVE-2019-10337

An XML external entities (XXE) vulnerability in Jenkins Token Macro Plugin 2.7 and earlier allowed attackers able to control a the content of the inp…

Fix: after 2.7
Fix from $1,950 2019-06-11
Emc Openmanage Server Administrator HIGH 7.5
CVE-2019-3722

Dell EMC OpenManage Server Administrator (OMSA) versions prior to 9.1.0.3 and prior to 9.2.0.4 contain an XML external entity (XXE) injection vulnera…

Mitigation only
Fix from $1,950 2019-06-06
Pipeline Maven Integration HIGH 8.1
CVE-2019-10327

An XML external entities (XXE) vulnerability in Jenkins Pipeline Maven Integration Plugin 1.7.0 and earlier allowed attackers able to control a tempo…

Fix: after 1.7.0
Fix from $1,950 2019-05-31
Zimbra Collaboration Suite CRITICAL 9.8
CVE-2018-20160

ZxChat (aka ZeXtras Chat), as used for zimbra-chat and zimbra-talk in Synacor Zimbra Collaboration Suite 8.7 and 8.8 and in other products, allows XX…

Fix: 8.7.11 / 8.8.9+
Fix from $2,300 2019-05-29
Zimbra Collaboration Suite CRITICAL 9.8
CVE-2019-9670 KEVEPSS 100%

mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XXE) vulnerability, as demonstr…

Fix: 8.7.11+
Fix from $2,300 2019-05-29
Camel HIGH 7.5
CVE-2019-0188EPSS 10%

Apache Camel prior to 2.24.0 contains an XML external entity injection (XXE) vulnerability (CWE-611) due to using an outdated vulnerable JSON-lib lib…

Fix: 2.24.0+
Fix from $1,950 2019-05-28
Contact Center\ CRITICAL 9.8
CVE-2018-8940

ClientServiceConfigController.cs in Enghouse Cloud Contact Center Platform 7.2.5 has functionality for loading external XML files and parsing them, a…

No fix yet
Fix from $2,300 2019-05-14
Enterprise Password Vault CRITICAL 9.8
CVE-2019-7442EPSS 40%

An XML external entity (XXE) vulnerability in the Password Vault Web Access (PVWA) of CyberArk Enterprise Password Vault <=10.7 allows remote attacke…

Fix: after 10.7
Fix from $2,300 2019-05-08
Tririga Application Platform HIGH 7.1
CVE-2019-4208

IBM TRIRIGA Application Platform 3.5.3 and 3.6.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote at…

Fix: 3.5.3.6 / 3.6.0.3+
Fix from $1,950 2019-05-07
Blogengine.net CRITICAL 9.8
CVE-2018-14485EPSS 16%

BlogEngine.NET 3.3 allows XXE attacks via the POST body to metaweblog.axd.

No fix yet
Fix from $2,300 2019-05-07
Manageengine Firewall Analyzer CRITICAL 9.8
CVE-2019-11677EPSS 9%

The Custom Report import function in Zoho ManageEngine Firewall Analyzer before 12.3 Build 123224 is vulnerable to XML External Entity (XXE) Injectio…

Mitigation only
Fix from $2,300 2019-05-02
Self Organizing Swarm Modules CRITICAL 9.3
CVE-2019-10309

Jenkins Self-Organizing Swarm Plug-in Modules Plugin clients that use UDP broadcasts to discover Jenkins masters do not prevent XML External Entity p…

Mitigation only
Fix from $2,300 2019-04-30
Printeron HIGH 7.7
CVE-2018-17169

An XML external entity (XXE) vulnerability in PrinterOn version 4.1.4 and lower allows remote authenticated users to read arbitrary files or conduct …

Fix: after 4.1.4
Fix from $1,950 2019-04-23
Front Office Server MEDIUM 6.5
CVE-2018-17289

An XML external entity (XXE) vulnerability in Kofax Front Office Server Administration Console version 4.1.1.11.0.5212 allows remote authenticated us…

No fix yet
Fix from $1,600 2019-04-18
Unified Endpoint Management HIGH 7.5
CVE-2019-8999

An XML External Entity vulnerability in the UEM Core of BlackBerry UEM version(s) earlier than 12.10.1a could allow an attacker to potentially gain r…

Fix: after 12.10.1a
Fix from $1,950 2019-04-18
Pdfbox CRITICAL 9.8
CVE-2019-0228EPSS 9%

Apache PDFBox 2.0.14 does not properly initialize the XML parser, which allows context-dependent attackers to conduct XML External Entity (XXE) attac…

Mitigation only
Fix from $2,300 2019-04-17
Hana MEDIUM 6.0
CVE-2019-0284

SLD Registration in SAP HANA (fixed in versions 1.0, 2.0) does not sufficiently validate an XML document accepted from an untrusted source. The attac…

Mitigation only
Fix from $1,600 2019-04-10
Windows 10 HIGH 8.8
CVE-2019-0790EPSS 16%

A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Executio…

Patch available
Fix from $1,950 2019-04-09
Windows 10 HIGH 8.8
CVE-2019-0791EPSS 17%

A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Executio…

Patch available
Fix from $1,950 2019-04-09
Windows 10 HIGH 8.8
CVE-2019-0792EPSS 17%

A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Executio…

Patch available
Fix from $1,950 2019-04-09
Windows 10 HIGH 8.8
CVE-2019-0793EPSS 17%

A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Executio…

Patch available
Fix from $1,950 2019-04-09
Windows 10 HIGH 8.8
CVE-2019-0795EPSS 21%

A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Executio…

Patch available
Fix from $1,950 2019-04-09
Kura HIGH 7.5
CVE-2019-10244

In Eclipse Kura versions up to 4.0.0, the Web UI package and component services, the Artemis simple Mqtt component and the emulator position service …

Fix: after 4.0.0
Fix from $1,950 2019-04-09
Windows 10 HIGH 8.8
CVE-2019-0756EPSS 12%

A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Executio…

Patch available
Fix from $1,950 2019-04-09
Airsonic CRITICAL 9.8
CVE-2018-20222

XXE issue in Airsonic before 10.1.2 during parse.

Fix: 10.1.2+
Fix from $2,300 2019-04-04
Sterling B2b Integrator HIGH 7.1
CVE-2019-4043

IBM Sterling B2B Integrator Standard Edition 5.2.0 snf 6.0.0.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML dat…

Fix: after 5.2.6.4
Fix from $1,950 2019-04-02
Crowd MEDIUM 6.5
CVE-2017-18110

The administration backup restore resource in Atlassian Crowd before version 3.0.2 and from version 3.1.0 before version 3.1.1 allows remote attacker…

Fix: 3.0.2+
Fix from $1,600 2019-03-29
Application Links HIGH 8.7
CVE-2017-18111

The OAuthHelper in Atlassian Application Links before version 5.0.10, from version 5.1.0 before version 5.1.3, and from version 5.2.0 before version …

Fix: 5.0.10 / 5.1.3+
Fix from $1,950 2019-03-29
Arcsight Logger HIGH 7.1
CVE-2019-3481

Mitigates a XML External Entity Parsing issue in ArcSight Logger versions prior to 6.7.

Fix: 6.7+
Fix from $1,950 2019-03-25